It is licensed, documented, and uses no install-time scripts. The package is abandoned in the registry, its repository is archived, and it has had no commits in the last three months; use october/debugbar instead.
15%
Total Score
25
100
64
100
Packagist marks the entire package as abandoned and identifies october/debugbar as its replacement. This is a severe adoption concern even though the assessed release is stable.
The repository recorded zero commits and zero active maintainers in the last three months. This reinforces the abandonment risk shown by the archived status.
The linked repository is archived, despite being pushed on April 9, 2026. An archived source repository is a strong indication that future maintenance and fixes should not be expected.
The registry namespace and repository are both owned by the rainlab organization. This provides clear ownership context, but organizational backing does not outweigh the archived repository and registry abandonment marker.
The package has existed since May 2016 with 19 releases and one release in the last 12 months. The recent release history provides maturity context but does not offset the package-wide abandonment status.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-11094 rainlab/debugbar-plugin is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.0 - 3.1.0. | 0.0.0 - 3.1.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
barryvdh/laravel-debugbar Version ^3.10.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.